Files
compor-academy/PORTAINER.md
Cauê Faleiros 7842a757cd
All checks were successful
CI / Validate frontend and API (push) Successful in 27s
CI / Build and publish Docker images (push) Successful in 44s
fix: use explicit Gitea registry credentials
2026-08-31 13:41:14 -03:00

40 lines
2.4 KiB
Markdown

# Portainer deployment
Use `docker-compose.yml` as a Portainer Stack from this repository. It deploys the frontend, API, and PostgreSQL as one internal Docker network. Only the web container exposes a port; it proxies `/api` to the API container.
This is a Docker Swarm stack: Portainer pulls prebuilt API and web images from the Gitea Container Registry. It never builds Dockerfiles itself.
## Gitea Actions registry secrets
Create these repository-level Action secrets in Gitea before pushing to `main`:
- `REGISTRY_USERNAME`: the Gitea username that owns a package-write token.
- `REGISTRY_TOKEN`: a Gitea personal access token for that user with package read/write permission.
The built-in Actions job token can be disabled or lack registry scope on self-hosted Gitea instances, so the image publishing job intentionally uses these explicit secrets.
## Required Portainer environment variables
- `POSTGRES_PASSWORD`: a long, unique database password. Avoid characters that are not URL-safe because it is used in `DATABASE_URL`.
- `JWT_SECRET`: a unique random string of at least 32 characters.
- `FRONTEND_ORIGIN`: the exact public application URL, for example `https://hub.example.com`.
Optional variables:
- `POSTGRES_DB` (default `compor_hub`)
- `POSTGRES_USER` (default `compor`)
- `WEB_PORT` (default `8080`)
- `IMAGE_TAG` (default `latest`; set a specific release tag when available)
- `API_IMAGE` and `WEB_IMAGE` only if the Gitea registry namespace differs from the defaults.
## Before publishing
1. Push to `main` and wait for Gitea Actions to publish `gitea.blyzer.com.br/blyzer/compor-academy-api:latest` and `gitea.blyzer.com.br/blyzer/compor-academy-web:latest`.
2. Ensure the Portainer endpoint can pull from the Gitea Container Registry. If the images are private, add Gitea registry credentials to the endpoint/stack deployment configuration.
3. Deploy the stack with a temporary `WEB_PORT` and verify `/api/v1/health` through the public domain.
4. Create the production administrator using the API container's console and `npm run db:bootstrap-admin`, with the `BOOTSTRAP_ADMIN_*` variables supplied only for that one command.
5. Place the web service behind HTTPS, normally through your existing reverse proxy (Traefik, Nginx Proxy Manager, or Cloudflare Tunnel), and set `FRONTEND_ORIGIN` to that HTTPS address.
6. Back up the `compor_postgres_data` volume before updates.
Do not expose port 5432 or port 3001 publicly.